How this DPA becomes binding
This Data Processing Addendum (“DPA”) forms part of the GHub AI Terms between PROGOS Kft. (“Processor”) and the organization accepting those Terms (“Controller”) where PROGOS processes personal data on the Controller’s behalf. If you require a countersigned copy, additional documented instructions, or a transfer assessment, contact info@progos.hu before using the beta with regulated or sensitive workloads.
1. Roles and scope
The Controller determines which accounts, data and commands are used. PROGOS acts as processor for Workspace content and related account configuration processed to perform those commands. PROGOS remains an independent controller for its own account administration, security, legal compliance and opt-in public-site analytics as described in the Privacy Policy.
“Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR. This DPA prevails over conflicting Terms only for processing governed by it.
2. Documented instructions
PROGOS processes Personal Data only on documented instructions: the Terms, this DPA, product configuration, scopes the Controller grants, and tool commands issued through an authorized client. PROGOS will inform the Controller if an instruction appears to infringe data-protection law, and may pause it. If law requires processing beyond instructions, PROGOS will notify the Controller before processing unless law prohibits notice.
3. Details of processing
| Subject matter | Providing a multi-account Gmail, Calendar and Tasks connector and related authentication, routing, security and support. |
|---|---|
| Duration | For the Service relationship and until deletion or return under section 10, with short technical retention described in Annex I. |
| Nature and purpose | Retrieve, transmit, format, create or update supported Workspace items on the Controller’s instruction; authenticate users; maintain authorized connections; secure and diagnose service operation. |
| Data subjects | Authorized users; email senders, recipients and contacts; meeting participants; task/event subjects; and other people whose data appears in connected Workspace accounts. |
| Data types | Identifiers, email addresses and headers, message content, calendar and task data, user commands, account configuration, authorization credentials, and shape-only operational metadata. |
| Special categories | Not intentionally required, but may appear in Workspace content selected by the Controller. The Controller must not use the closed beta for special-category or criminal-offence data unless it has established a lawful basis, safeguards and written suitability agreement with PROGOS. |
4. Confidentiality and personnel
PROGOS ensures that people authorized to process Personal Data are bound by confidentiality and receive access only where needed for operation, security or support. Access is reviewed and removed when no longer required.
5. Security
PROGOS implements the measures in Annex II, taking account of the state of the art, costs, scope and risk. The Controller is responsible for securing its Google and client accounts, limiting scopes and users, reviewing consequential writes, and not using the beta where its risk assessment requires controls the beta does not yet provide.
6. Subprocessors
The Controller gives general authorization for the subprocessors in Annex III. PROGOS will post or otherwise provide notice of an intended material addition or replacement and allow a reasonable objection based on substantiated data-protection grounds. The parties will seek a practical resolution; if none is available, the Controller may stop the affected use. PROGOS imposes materially equivalent data-protection duties on subprocessors and remains responsible for their performance to the extent required by GDPR Article 28.
A connector client independently selected and contracted by the Controller (for example Claude/Anthropic) is not a PROGOS subprocessor merely because the Controller instructs GHub AI to send a tool result there. The Controller is responsible for authorizing and governing that recipient.
7. International transfers
Where PROGOS transfers Controller Personal Data outside the EEA without an adequacy decision, the applicable EU Standard Contractual Clauses are incorporated as the transfer mechanism, using Module Two (controller to processor) where applicable, together with supplementary measures in Annex II. The parties will provide information reasonably needed for a transfer-risk assessment.
8. Data-subject requests and assistance
Taking account of the processing, PROGOS will reasonably assist the Controller with data-subject rights, DPIAs, prior consultations and compliance information. If PROGOS receives a request relating to Controller data, it will direct the person to the Controller unless authorized to respond. The Controller remains responsible for the response and lawful instructions. Disproportionate bespoke work may require an agreed fee; ordinary self-service deletion is included.
9. Personal data breaches
PROGOS will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Controller data, and provide available information about its nature, likely consequences, affected data and subjects, and mitigation. Notification is not an admission of fault. The Controller decides whether its authority or data subjects must be notified.
10. Return and deletion
At the Controller’s choice, the dashboard can disconnect individual Google identities or delete the GHub AI profile. At termination, PROGOS deletes or returns Controller Personal Data unless Union or Member State law requires retention. Deletion immediately blocks ordinary profile use. If local account, pending-grant or Secret Manager cleanup is interrupted, the blocked profile fields, account configuration and credentials remain only as needed for automatic idempotent retry. After local account and token removal, the durable job retains only the profile identifier, legal acceptance and cleanup state until Firebase session revocation and Auth-user deletion are verified. Both phases retry automatically across service revisions. A minimal profile deletion tombstone then remains for up to one hour, and a one-way-hashed OAuth revocation marker remains through the configured connector-token lifetime plus a one-hour buffer, solely to stop concurrent requests or old tokens from recreating access; Firestore TTL then removes them. Workspace content is not persistently stored by the application. Backups and other provider TTL cleanup may take their normal secure expiry period; during that period data remains protected and unavailable for ordinary use.
11. Information and audits
PROGOS will make information reasonably necessary to demonstrate Article 28 compliance available. No more than once annually, unless required by an authority or incident, the Controller may request a remote audit with at least 30 days’ notice. Audits must protect other customers, security and confidential information, use independent qualified auditors, and avoid service disruption. Existing reports and answers should be used before intrusive testing. Each party bears its costs unless material non-compliance is found.
Annex I — Retention instructions
- Workspace content: transient for the tool request; no application content store.
- Connected-account configuration and refresh token: until disconnect or profile deletion.
- Shape-only telemetry and intentionally submitted feature reports: 90 days.
- Cloud service logs: 30 days in the production default log bucket.
- Session: up to 14 days; connector access tokens: configured lifetime, currently 30 days; pending authorization artifacts: logically available for 60 seconds to 10 minutes depending on purpose. Unsaved Google refresh tokens use isolated Secret Manager secrets and shared Firestore cleanup records so scaling or a revision change cannot orphan the revocation handle.
- Saved-account secret provisioning uses a token-free Firestore reservation (pseudonymous user id, slug and secret reference): normally removed atomically at commit, bounded to 2 minutes for provisioning and 5 minutes for commit recovery, but retained after a failed remote deletion only until verified cleanup succeeds.
- Deletion recovery blocks ordinary profile use and durably retries interrupted local account/token cleanup; once local cleanup succeeds, it retains only the profile identifier, legal acceptance and deletion state until idempotent session/Auth-user cleanup is verified.
- Deletion barriers: minimal profile tombstone up to 1 hour; one-way-hashed OAuth revocation marker through the configured connector-token lifetime plus a one-hour buffer (currently up to 30 days + 1 hour).
Annex II — Technical and organizational measures
- TLS in transit and provider-managed encryption at rest.
- Google refresh tokens isolated in a dedicated Secret Manager namespace; connector access tokens stored only as SHA-256 hashes.
- Firebase session verification with revocation checks; OAuth 2.1 authorization code flow with PKCE, single-use codes, redirect allowlists and short expiries.
- Per-user Firestore paths, authorization boundaries and deletion tombstones that block delayed credential writes; no account secrets serialized to the browser.
- Least-privilege runtime identity, dataset-scoped access, controlled deployment and dependency checks.
- Scope checks before write tools, explicit per-account escalation, and no permanent-delete tool.
- Shape-only telemetry schema, 90-day BigQuery partition expiry, and 30-day Cloud Logging retention.
- Self-service token revocation, account disconnect, session revocation and profile deletion.
- Incident investigation and notification procedure proportionate to the closed beta.
Annex III — Authorized subprocessors
| Provider | Service and data | Location/transfer |
|---|---|---|
| Google Cloud / Firebase group contracting entity and published subprocessors | Hosting, Cloud Run compute, Firebase Authentication, Firestore configuration, Secret Manager credentials, BigQuery telemetry, Cloud Logging and supporting infrastructure. | Primary production configuration in the EU (europe-west1 where supported); global support/operations subject to Google’s data processing terms, SCCs and published locations. |
| Google Workspace APIs | Source/destination selected by the Controller for Gmail, Calendar and Tasks requests. | Under the Controller’s Google relationship and Google’s applicable regional/transfer terms. |
Contact for this DPA: info@progos.hu. Provider: PROGOS Számítástechnikai Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság, 1121 Budapest, Ordas köz 2., Hungary, company number 01-09-718243.